Re: Curious about iptables and ping behavior
On Fri, 12 Apr 2002 22:32:59 -0400 (EDT)
Nick Busigin <email@example.com> wrote:
> I'm a little puzzled by the following behavior...
> iptables -I INPUT x -s 126.96.36.199/24 -j DROP
> iptables -I INPUT x -d 188.8.131.52/24 -j DROP
> As I understand it, those rules should block anything coming or going
> to/from the specified IP address range.
You need to apply those rules on all chains, INPUT, OUTPUT, and FORWARD in order to block all incomming and outgoing traffic on your host.
> While ping (at the command line) appeared to not return anything, my DSL
> modem lights and tcpdump showed a different story. This looks pretty
> strange to me.
> Anyone willing to shed some light on this behavior?
A DSL modem is both a modem and a router (some even have bridging functionality). Your ICMP echo request flow's through the multihomed host and then back again before being dropped by IPTables. tcpdump is simply seing what's on the line between you and your router :)
To UNSUBSCRIBE, email to firstname.lastname@example.org
with a subject of "unsubscribe". Trouble? Contact email@example.com